Courseiva
AI and Network OperationsmediumMultiple ChoiceObjective-mapped

CCNA AI and Network Operations Practice Question

A network engineer at a large enterprise observes repeated spikes in latency on the core network every weekday at 10:00 AM, but no corresponding increase in overall bandwidth utilization. The engineer wants to use AI/ML to automatically identify the root cause and take corrective action without manual intervention. Which concept best describes this approach?

⚠ Common exam trap

Cisco often tests the distinction between a single AI/ML technique (like anomaly detection) and the full closed-loop automation framework (IBN), leading candidates to pick the narrower answer when the question explicitly requires both detection and automated corrective action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Intent-based networking

Intent-based networking (IBN) is correct because it describes a closed-loop system where the network continuously validates that its operational state matches the desired business intent. In this scenario, the engineer wants the network to automatically detect the latency anomaly, correlate it with other telemetry (e.g., routing changes, queue drops), and take corrective action (e.g., reroute traffic, adjust QoS) without human intervention — which is the core promise of IBN, often implemented via Cisco's DNA Center with Assurance and AI/ML capabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Anomaly detection

    Why it's wrong here

    Anomaly detection is a monitoring function that flags statistically unusual behavior — such as a latency spike — using thresholds, baselines, or ML models, but it stops at alerting. It does not include the closed-loop policy enforcement needed to automatically modify network configuration. In this scenario, the system must both detect the deviation and reconfigure the network to restore the intended state, which anomaly detection alone cannot perform.

  • Intent-based networking

    Why this is correct

    Intent-based networking (IBN) uses closed-loop automation to continuously monitor the network, detect when the actual state deviates from the intended state (e.g., latency spikes), and automatically reconfigure the network to restore the intent. This matches the scenario of automatic identification and correction.

  • Predictive analytics

    Why it's wrong here

    Predictive analytics focuses on the future, not the present: it ingests historical and streaming data to forecast events like link failure or congestion before they happen. It supports proactive planning but does not react to an existing anomaly in real time. The scenario describes an automatic response to a current latency spike, which is a reactive, closed-loop action rather than a future-oriented prediction.

  • Machine learning classification

    Why it's wrong here

    Machine learning classification is a specific technique that categorizes data points into classes (for example, labeling traffic as normal or anomalous) but it is not a complete automation system. A classifier produces a label or score; it lacks the intent, policy, and actuation mechanisms to determine the appropriate corrective action and apply it to the network. Therefore, it could serve as a component inside an intent-based system, but by itself it cannot both identify and correct the problem.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

Intent-based networkingCorrect answer

Why this is correct

Intent-based networking (IBN) uses closed-loop automation to continuously monitor the network, detect when the actual state deviates from the intended state (e.g., latency spikes), and automatically reconfigure the network to restore the intent. This matches the scenario of automatic identification and correction.

Anomaly detectionWrong answer — click to see why

Why this is wrong here

Anomaly detection identifies unusual patterns like latency spikes, but it does not include automatic corrective action. The scenario requires both detection and automated response, which anomaly detection alone cannot provide.

Why candidates choose this

Students may think anomaly detection is sufficient because it can identify the latency spikes, but they overlook the requirement for automatic corrective action without manual intervention.

Predictive analyticsWrong answer — click to see why

Why this is wrong here

Predictive analytics forecasts future events (e.g., predicting when a link will fail), but it does not automatically take corrective action. The scenario involves detecting and correcting an existing anomaly, not predicting a future one.

Why candidates choose this

Students might confuse predictive analytics with proactive detection, but the scenario describes an ongoing issue that needs immediate correction, not prediction of future events.

Machine learning classificationWrong answer — click to see why

Why this is wrong here

Machine learning classification categorizes data (e.g., classifying traffic as normal or anomalous), but it does not inherently include automated corrective actions. The scenario requires a system that both detects and corrects.

Why candidates choose this

Students may think classification can identify the root cause, but classification alone does not trigger automated corrective actions; it only labels data.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.